Privacy Notice
What we collect, why we are allowed to, who else touches it, how long we keep it and how to make us stop. Short on purpose: a notice nobody finishes reading protects nobody.
Who we are
Decision Intel is the controller for the personal data described in this notice. We are established in United Kingdom (formation pending), at Address to be confirmed on incorporation, Founder is currently UK-resident; legal entity formation in progress..
Our named contact for data protection is Folahan Williams, Founder & CEO, reachable at compliance@decision-intel.com. General procurement and vendor-risk questions go to team@decision-intel.com.
The distinction that matters most
We hold two different kinds of data and treat them differently, so it is worth separating them before anything else.
- Account data — your name, work email, and the records of your use of the platform. For this we are the controller, and this notice describes what we do with it.
- The documents you upload — deal papers, memos, filings. For anything personal inside them we are your processor: we act on your instructions, for the purpose of producing your audit, and for nothing else. Your own privacy notice governs the people named in those documents, not ours.
We do not train models on your documents, and we do not use them to improve the service for anyone else.
What we collect
- Identity and contact — name, work email, and the organisation you say you belong to.
- Authentication — sign-in method and session records. We never see your Google password; where you set one with us it is stored only as a hash.
- Content — the documents you upload and the audits produced from them.
- Usage — pages visited, features used, and errors encountered, in aggregate.
- Technical — IP address and browser type, from server logs, used for security and abuse prevention.
We do not ask for and do not want special-category data. Please do not upload documents whose purpose is to convey health, biometric, or similar sensitive information about identifiable people.
Why we are allowed to process it
Article 13(1)(c) requires us to name a lawful basis for each activity rather than one for everything. The table below is that.
Necessary to provide the service you asked for. Without it the platform cannot function.
Required to deliver the service and to meet our incident-notification commitments.
Needed to find errors and improve the product. Balanced by collecting event counts rather than people, and by your right to object below.
Accountability under GDPR Art 5(2) and record-keeping expectations under EU AI Act Art 14 require retained logs of sensitive actions.
Sent only if you opt in, and you can withdraw at any time without affecting the service.
Who else processes it
We use a small number of sub-processors, listed below with what each one touches. The full schedule, with regions and compliance posture, is maintained alongside our security documentation and forms part of the data processing agreement.
≥30 days written notice via security@decision-intel.com before activation; Customer right to object in writing within 14 days, with cure path defined per DPA §6.
Application code, environment variables, server-side request handling. No persistent customer content storage.
Customer accounts, user settings, encrypted document content (AES-256-GCM at rest), audit log rows, all platform metadata.
Anonymised document text (PII scrubbed by the GDPR anonymizer node first). No training right; logged on Vercel-side cost-tracker only.
Anonymised document text (same anonymizer pre-pass as Gemini). No training right.
Billing email, subscription state, payment intent IDs. Decision Intel never sees or stores card numbers; PCI-DSS responsibility lives with Stripe.
Customer email address + transactional message content (auth flows, magic links, password resets, account notifications).
Error stack traces, request metadata, performance spans. PII scrubbers enabled at the SDK layer; no body content captured.
DNS lookups for decision-intel.com domains; inbound *@decision-intel.com email routing to founder Gmail. No persistent message storage.
Where it goes
Some sub-processors operate outside the UK and EEA. Where personal data is transferred there, the transfer is made under the UK International Data Transfer Addendum or the EU Standard Contractual Clauses, together with the supplementary measures described in our security documentation.
A copy of the transfer mechanism relied on for a specific sub-processor is available on request.
How long we keep it
- Documents and audits — for as long as your account holds them. You can delete a document at any time, and deletion removes the content and its derived analyses.
- Deleted content — purged within 30 days of deletion, including from backups on their normal rotation.
- Account data — for the life of the account, then deleted within 30 days of closure.
- Audit logs — retained for the period required for security and accountability, then deleted on a rolling schedule.
- Records we are legally required to keep — for the period the law requires, and no longer.
How it is protected
Document content is encrypted at rest with AES-256-GCM under versioned keys, and everything in transit runs over TLS 1.2 or better. Access is restricted to the personnel who need it, and sensitive actions are logged.
The full posture — encryption, key rotation, sub-processor schedule, incident response and regulatory mapping — is on the security page rather than repeated here, so there is one description of it rather than two that can drift apart.
Cookies
We use cookies that are strictly necessary to keep you signed in and to protect against cross-site request forgery. These cannot be switched off without breaking sign-in.
Anything beyond that is optional, off until you opt in, and changeable at any time from the cookie settings in your browser session.
Your rights
Under UK and EU GDPR you have the rights below. Exercise any of them by writing to the contact in §1; we respond within one month, and will tell you if we need longer and why.
- Access — ask what we hold about you and get a copy.
- Rectification — have inaccurate data corrected.
- Erasure — have your data deleted, subject to logs we are required to keep.
- Restriction — have processing paused while a dispute is resolved.
- Portability — receive your data in a machine-readable form, or have it sent to another provider.
- Objection — object to processing that rests on legitimate interest, including the analytics above.
- Withdraw consent — at any time, where consent was the basis.
- Human review — where a decision about you would be made by automated means alone, ask for a person to review it. We do not currently make such decisions.
Complaints
If you think we have handled your data badly, tell us first — we would rather fix it. If you are not satisfied, you can complain to the UK Information Commissioner’s Office at ico.org.uk, or to the supervisory authority in your EU member state. You do not need our permission to do so.
Changes
We will update this notice when our processing changes. Material changes are notified to account holders before they take effect. The date at the top is the current version.